Security Engineer (App Sec and Cloud Infra)

Thumbtack
United States
Workplace: RemoteFull timeFunction: CybersecurityExperience: 4+ yearsSkills: ["Ownership","Communication","Collaboration","Growth mindset","Independent execution"]

Own and deliver application security work across defined projects, partnering with engineering to identify, prioritize, and remediate risks. Build secure-by-default patterns and approved architectures while integrating cloud security controls into CI/CD, IAM, networking, and runtime environments. Participate in design reviews, threat modeling, and security incident response, writing code, performing reviews, and documenting fixes to reduce recurring vulnerability classes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thumbtack
Thumbtack
6 months ago

Security Engineer (App Sec and Cloud Infra)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Own and deliver application security work across defined projects, partnering with engineering to identify, prioritize, and remediate risks. Build secure-by-default patterns and approved architectures while integrating cloud security controls into CI/CD, IAM, networking, and runtime environments. Participate in design reviews, threat modeling, and security incident response, writing code, performing reviews, and documenting fixes to reduce recurring vulnerability classes.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own and deliver application security work within defined projects or domains.
  • •Contribute to cross-functional security initiatives by executing clearly scoped pieces of larger efforts.
  • •Identify, prioritize, and help remediate application security risks in partnership with engineering teams.
  • •Apply secure-by-default patterns and approved architectures when designing or reviewing systems.
  • •Integrate security controls into CI/CD pipelines, IAM, networking, and runtime environments, and support incident response and post-incident remediation.

Key Requirements

  • •4+ years of experience in software engineering, application security, or cloud infrastructure security.
  • •Practical experience with application security techniques including threat modeling, secure design patterns, authentication/authorization, secrets management, and vulnerability remediation.
  • •Strong understanding of secure coding practices and common application security risks, including OWASP Top 10.
  • •Experience securing cloud-native systems in AWS and/or GCP.
  • •Ability to assess security risks, reason about tradeoffs, and deliver practical, risk-informed security improvements with strong written and verbal communication.
Experience:4+ years
Skills:OwnershipCommunicationCollaborationGrowth mindsetIndependent execution
Tech Stack:AWSGCPCI/CDIAMNetworkingOWASP Top 10

Company Brief

Thumbtack
Provides an online marketplace connecting local service professionals (home improvement, events, lessons, and more) with customers seeking quotes, reviews, and booking tools to hire vetted contractors and providers.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2008
WebsiteLinkedIn